Cue Omni Reader for DeepSeek Harness: registers the audited omni-reader-mcp MCP server so its URL/file parse tools surface as mcp__omni__ (parse, get_parse_status, read_result, read_outline, save_result, discard_result, cancel_parse).
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:sensedeal/cue-skills#path:/dsh/cue-omni-reader
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
A DeepSeek Harness bundle that registers the
audited Cue Omni Reader MCP server so its tools surface as native mcp__omni__*
tools in any Harness profile. It is a thin composition layer — DSH exposes the tools
through @deepseek-ai/dsh-mcp-client; this bundle only wires the server row and its
configuration, and ships no custom parser or MCP driver.
What the tools do: parse / get_parse_status / cancel_parse / read_result /
read_outline / discard_result / save_result — turn an HTTP(S) URL or an
authorized local document, audio, or video source into content.
The skill-facing guidance (same capability, agent-loadable instructions) ships separately in this repo as
cue-omni-reader/. Install both to get the tools and the guided flow.
Prerequisites
- Node.js ≥ 20.12 (the Bridge runtime).
- A Cue API key from https://cuecue.cn/hub/api-key. New accounts get free credits (see the skill's setup reference for current allowances).
- The Bridge is spawned via
npx -y @cueai/omni-reader-mcp@1.8.6, so the npm registry must be reachable, or pin an install whose binary is onPATH.
Install
Install the bundle into a profile (pnpm-managed; it auto-joins the profile's
bundle stack because it declares dsh.bundle):
dsh plugin --profile web add @cueai/dsh-omni-reader
# or from a local checkout / git spec:
dsh plugin --profile web add ./dsh/cue-omni-reader
Alternative one-off apply (no package):
dsh web --patch ./dsh/cue-omni-reader/cordis.patch.yml
Configure
The server row's env is env-driven (no secrets or absolute paths in this file):
| Env var | Meaning | Default |
|---|---|---|
CUE_API_KEY |
Cue Omni credential | required — set in $DSH_HOME/.env or export before launching dsh |
OMNI_ALLOWED_ROOTS |
:-separated absolute dirs the Bridge may read |
process.cwd() (the dsh working dir) |
Set the key and (optionally) a root, then restart dsh so the layered .env/config
takes effect:
# ~/.dsh/.env
CUE_API_KEY=sk-...
OMNI_ALLOWED_ROOTS=/home/you/workspace
Usage
After a restart the model sees:
mcp__omni__parse mcp__omni__get_parse_status mcp__omni__cancel_parse
mcp__omni__read_result mcp__omni__read_outline mcp__omni__discard_result
mcp__omni__save_result
Call mcp__omni__parse with a source (URL or an allowed-root path), poll
mcp__omni__get_parse_status, and consume the result.
Verify
dsh --profile web --dump-config # the tree should include an `mcp-omni` row
# then, in a session, confirm the tools appear and a small parse succeeds.
Security & scope
- Omni can parse any URL — that is an arbitrary network / egress surface.
Keep
OMNI_ALLOWED_ROOTSto the minimum directories the agent actually needs, and give consent before exposing URL parsing to an unattended agent. - Local file reads are bounded by
OMNI_ALLOWED_ROOTS; the Bridge scrubs ambient credential-ish env before launching the child. - Do not put the API key in chat, command arguments, this file, logs, or generated JSON. Rotate it if it ever appears in plaintext.
Versioning
- Bridge pin:
@cueai/omni-reader-mcp@1.8.6(audited; never an implicitlatest). @deepseek-ai/dsh-mcp-clientis a peer dependency (declared as^0.1.1-rc.2); the Harness profile provides it. Align it to the Harness release you run if needed.
Rollback
dsh plugin --profile web remove @cueai/dsh-omni-reader
# or delete the `mcp-omni` insert from your profile's cordis.patch.yml.
License
MIT — see LICENSE.
Links
More in this category
Tencent/WeKnora#dsh-weknora★ 32466
Four read-only tools over a WeKnora knowledge base: list knowledge bases, hybrid passage search, reassemble one document's chunks in order, and WeKnora's own cited RAG or ReAct-agent answer with a resumable session id.
superdesigndev/treg★ 4760
Tool catalog for agents: search ~2,600 external endpoints (SEO and SERP, backlinks, social, people and company enrichment, ad libraries, scraping) by the task you want done, read each one's parameters and per-call price, then call it with the credential injected server-side. Ships the skill plus an MCP row that stays disabled until TREG_TOKEN is set.
TencentCloudBase/CloudBase-AI-Toolkit#dsh-plugin★ 1132
Tencent CloudBase backend for DeepSeek Harness — scaffold and deploy full-stack apps from chat, render query results as table cards with paging, sorting and CSV export, preview a deployment on its domain, and call the CloudBase MCP toolset (`mcp__cloudbase__*`) with device-code login.
gitroomhq/postiz-agent#dsh-postiz★ 506
Connects DeepSeek Harness to Postiz over MCP: list connected social media channels, fetch per-platform posting rules, and schedule, draft, or publish posts to X, LinkedIn, Instagram, Facebook, Threads, TikTok, YouTube, Reddit, Bluesky, Mastodon, Discord, Slack, Telegram and more; adds a postiz workflow skill.
EthanYoQ/Invoice-Downloader#dsh-invoice-downloader★ 500
Local IMAP invoice download, OCR, archive, and Excel reimbursement summaries for DeepSeek Harness.
anysearch-team/anysearch-dsh★ 450
AnySearch-powered real-time web and vertical search provider for DeepSeek Harness.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.